Cybersecurity Research

Cisco Talos Unveils CAIRN, a New Way to Track AI-Powered Malware

Cisco Talos · 22 Sept 2026
Key Takeaway Businesses should stay alert to the fact that AI is now being built into malware itself, and should ensure their security vendors and threat intelligence feeds are tracking this emerging category of threats.

Cisco Talos has introduced CAIRN (Cognitive Artifact Intelligence Research Network), a research toolkit designed to hunt, classify and track a growing category of threats: malware that integrates with, targets or abuses AI systems. The idea behind CAIRN is that attackers building AI-integrated malware inevitably leave behind digital traces, such as prompt templates, API keys, provider endpoints and jailbreak terms, embedded in their tools. Talos calls these traces 'cognitive artifacts' and uses them to identify malicious activity without needing to download or run the actual malware.

CAIRN works entirely from metadata, combining rule-based detection, semantic clustering and relationship graph mapping to spot AI-integrated malware. It uses up to 24 acquisition filters to search across strings, sandbox behaviour and antivirus detection labels, then stores results in a structured database for analysis. An 'explorer layer' builds a graph of relationships between artifacts, helping defenders link together related malware families, infrastructure and threat actors.

Talos says it will progressively share findings from CAIRN, starting with a case study named CLOSEDQUORUM. This approach reflects a broader shift in the threat landscape, as attackers increasingly build AI capabilities directly into their malicious tooling, and defenders need new, scalable ways to detect and track that activity early.

AI security malware research Cisco Talos threat intelligence emerging threats
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Cisco Talos. We link back to every original so you can read it yourself.